2023 CVE Vulnerabilities
31,244 CVEs published in 2023.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-52175 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Michael Uno (miuno... |
| CVE-2023-7069 | MEDIUM | 5.4 | 0.3% | Feb 1, 2024 | The Advanced iFrame plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'advanced_iframe'... |
| CVE-2023-5390 | MEDIUM | 5.3 | 0.6% | Jan 31, 2024 | An attacker could potentially exploit this vulnerability, leading to files being read from the Honeywell Experion Contro... |
| CVE-2023-50166 | MEDIUM | 6.1 | 0.3% | Jan 31, 2024 | Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. |
| CVE-2023-47116 | MEDIUM | 5.3 | 0.7% | Jan 31, 2024 | Label Studio is a popular open source data labeling tool. The vulnerability affects all versions of Label Studio prior t... |
| CVE-2023-6780 | MEDIUM | 5.3 | 2.7% | Jan 31, 2024 | An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the sy... |
| CVE-2023-5992 | MEDIUM | 5.9 | 1.2% | Jan 31, 2024 | A vulnerability was found in OpenSC where PKCS#1 encryption padding removal is not implemented as side-channel resistant... |
| CVE-2023-7043 | MEDIUM | 5.5 | 0.3% | Jan 31, 2024 | Unquoted service path in ESET products allows to drop a prepared program to a specific location and run on boot with t... |
| CVE-2023-50357 | MEDIUM | 5.4 | 0.4% | Jan 31, 2024 | A cross site scripting vulnerability in the AREAL SAS Websrv1 ASP website allows a remote low-privileged attacker to gai... |
| CVE-2023-50356 | MEDIUM | 6.5 | 0.3% | Jan 31, 2024 | SSL connections to some LDAP servers are vulnerable to a man-in-the-middle attack due to improper certificate validation... |
| CVE-2023-2439 | MEDIUM | 5.4 | 0.3% | Jan 31, 2024 | The UserPro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'userpro' shortcode in versions up... |
| CVE-2023-46230 | MEDIUM | 4.9 | 0.4% | Jan 30, 2024 | In Splunk Add-on Builder versions below 4.1.4, the app writes sensitive information to internal log files. |
| CVE-2023-36259 | MEDIUM | 5.4 | 0.4% | Jan 30, 2024 | Cross Site Scripting (XSS) vulnerability in Craft CMS Audit Plugin before version 3.0.2 allows attackers to execute arbi... |
| CVE-2023-7225 | MEDIUM | 5.4 | 0.5% | Jan 30, 2024 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the width and heig... |
| CVE-2023-51813 | MEDIUM | 6.5 | 0.4% | Jan 30, 2024 | Cross Site Request Forgery (CSRF) vulnerability in Free Open-Source Inventory Management System v.1.0 allows a remote at... |
| CVE-2023-37571 | MEDIUM | 6.1 | 0.3% | Jan 30, 2024 | Softing TH SCOPE through 3.70 allows XSS. |
| CVE-2023-4554 | MEDIUM | 6.5 | 0.4% | Jan 29, 2024 | Improper Restriction of XML External Entity Reference vulnerability in OpenText AppBuilder on Windows, Linux allows Serv... |
| CVE-2023-4553 | MEDIUM | 5.3 | 0.4% | Jan 29, 2024 | Improper Input Validation vulnerability in OpenText AppBuilder on Windows, Linux allows Probe System Files. AppBuilder... |
| CVE-2023-30970 | MEDIUM | 6.5 | 0.5% | Jan 29, 2024 | Gotham Table service and Forward App were found to be vulnerable to a Path traversal issue allowing an authenticated use... |
| CVE-2023-22836 | MEDIUM | 5.4 | 0.3% | Jan 29, 2024 | In cases where a multi-tenant stack user is operating Foundry’s Linter service, and the user changes a group name from t... |
| CVE-2023-40551 | MEDIUM | 5.1 | 0.4% | Jan 29, 2024 | A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposu... |
| CVE-2023-40550 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim when it tried to validate the SBAT information. This issue may expose sensi... |
| CVE-2023-40549 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE bin... |
| CVE-2023-40546 | MEDIUM | 5.5 | 0.4% | Jan 29, 2024 | A flaw was found in Shim when an error happened while creating a new ESL variable. If Shim fails to create the new varia... |
| CVE-2023-7200 | MEDIUM | 6.1 | 0.4% | Jan 29, 2024 | The EventON WordPress plugin before 4.4.1 does not sanitise and escape a parameter before outputting it back in the page... |
Check if your code is affected by 2023 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now